Pages:
Author

Topic: Avatar (Read 1875 times)

legendary
Activity: 1778
Merit: 1043
#Free market
February 10, 2015, 01:56:49 PM
#30

You are welcome, I hope to see again the possibility to upload Cheesy or better use an avatar in the new forum software.
hero member
Activity: 658
Merit: 500
February 10, 2015, 01:41:55 PM
#29
global moderator
Activity: 3990
Merit: 2717
Join the world-leading crypto sportsbook NOW!
February 10, 2015, 01:39:06 PM
#28
What is the situation with being unable to change the profile avatar at this time?
I dont see why is it important at all?
Avatar is just a picture which represents nothing.
As it is a serioius forum I think that avatar is not good idea as anyone can upload picture by its own choice which can be rude, nude or sick. And banning a preson because of avatar is funny too. Thats why there is no avatar.

I have argued in other thread that avatars make easier to identify different people, since our brains process images faster than text.

This is true, though scammers could capitalise on this and that's why it might be a good idea limiting avatars to higher ranks than Newbies. NSFW avatars likely won't be allowed though.
legendary
Activity: 1778
Merit: 1043
#Free market
February 10, 2015, 01:38:04 PM
#27

So, if I insert this file using an tag, will I get all these flashy things? I don't seem to understand.

No , I don't think.  (I think)The hacker/s have inject the code into an image and after uploaded this image as avatar.

OK, but how was this “image” run, then?


I've find a great thread here in the forum : https://bitcointalksearch.org/topic/about-the-recent-attack-306878

hero member
Activity: 658
Merit: 500
February 10, 2015, 01:36:32 PM
#26
What is the situation with being unable to change the profile avatar at this time?
I dont see why is it important at all?
Avatar is just a picture which represents nothing.
As it is a serioius forum I think that avatar is not good idea as anyone can upload picture by its own choice which can be rude, nude or sick. And banning a preson because of avatar is funny too. Thats why there is no avatar.

I have argued in other thread that avatars make easier to identify different people, since our brains process images faster than text.
sr. member
Activity: 518
Merit: 250
Presale is live!
February 10, 2015, 01:25:03 PM
#25
What is the situation with being unable to change the profile avatar at this time?
I dont see why is it important at all?
Avatar is just a picture which represents nothing.
As it is a serioius forum I think that avatar is not good idea as anyone can upload picture by its own choice which can be rude, nude or sick. And banning a preson because of avatar is funny too. Thats why there is no avatar.
hero member
Activity: 658
Merit: 500
February 10, 2015, 01:08:39 PM
#24

So, if I insert this file using an tag, will I get all these flashy things? I don't seem to understand.

No , I don't think.  (I think)The hacker/s have inject the code into an image and after uploaded this image as avatar.

OK, but how was this “image” run, then?
legendary
Activity: 1778
Merit: 1043
#Free market
February 10, 2015, 01:07:33 PM
#23

So, if I insert this file using an tag, will I get all these flashy things? I don't seem to understand.

No , I don't think.  (I think)The hacker/s have inject the code into an image and after uploaded this image as avatar.
hero member
Activity: 658
Merit: 500
February 10, 2015, 01:03:54 PM
#22

So, if I insert this file using an tag, will I get all these flashy things? I don't seem to understand.
legendary
Activity: 1778
Merit: 1043
#Free market
February 10, 2015, 12:50:40 PM
#21
The feature was removed due to an exploit involving avatars. Only older users (such as myself) have them.

Where can I see how that exploit worked? I'm interested because I don't want the same happening to me when I develop a web platform.

This is the payload :

https://gist.githubusercontent.com/super3/6802808/raw/4af8de8037a7079d30236c608e1247370849f585/gistfile1.txt

and this is the video :

https://www.youtube.com/watch?v=LKrOHAfMdxI

and here an article :

http://www.coindesk.com/bitcointalk-forum-hacked-hole-seekers/
hero member
Activity: 658
Merit: 500
February 10, 2015, 10:28:10 AM
#20
The feature was removed due to an exploit involving avatars. Only older users (such as myself) have them.

Where can I see how that exploit worked? I'm interested because I don't want the same happening to me when I develop a web platform.
hero member
Activity: 840
Merit: 1000
February 10, 2015, 10:20:45 AM
#19
What is the situation with being unable to change the profile avatar at this time?

Not only at this time, but for over a year - there was an exploit associated with it, so that feature was disabled. As soon as the new forum software is up and running, perhaps later this month, we should have that option back again.

Hmm, I wait for a long time, I hope they can update asap, I really need to change my avatar, I don't like my current one(feathercoin logo)  Grin
legendary
Activity: 1638
Merit: 1010
https://www.bitcoin.com/
February 07, 2015, 06:19:21 AM
#18
Think he's talking about this: https://bitcointalksearch.org/topic/how-to-get-an-avatar-on-the-forum-right-now-914176

Yes, just in your signature so not really an avatar though it is pretty cool.
Yep, thats the one.
I've read so many posts since then i guess i kinda got mixed up.
Still if ya desperate.
global moderator
Activity: 3990
Merit: 2717
Join the world-leading crypto sportsbook NOW!
February 07, 2015, 06:13:01 AM
#17
Think he's talking about this: https://bitcointalksearch.org/topic/how-to-get-an-avatar-on-the-forum-right-now-914176

Yes, just in your signature so not really an avatar though it is pretty cool.
legendary
Activity: 1778
Merit: 1043
#Free market
February 07, 2015, 06:10:59 AM
#16
There was a post i read not long ago where som member had written a code or similar that alowed users to modify it and then put that in there personal text spot.
After doing this you would have a piture where your personal text would be.
I will try find a link and edit this post, i do remember b!z did it and confirmed.

No you can put it only in the signature space, not in the personal message.  This is the thread : https://bitcointalksearch.org/topic/how-to-get-an-avatar-914173
legendary
Activity: 1638
Merit: 1010
https://www.bitcoin.com/
February 07, 2015, 06:09:56 AM
#15
There was a post i read not long ago where som member had written a code or similar that alowed users to modify it and then put that in there personal text spot.
After doing this you would have a piture where your personal text would be.
I will try find a link and edit this post, i do remember b!z did it and confirmed.
legendary
Activity: 2562
Merit: 1071
February 07, 2015, 06:03:53 AM
#14
I thought he was talking about just fixing it so avatars could be re-enabled.

Hmm, that was my impression as well. Smiley

I just went on to say that they did supposedly fix the issue, but that, in addition to the reasons you stated, they probably weren't really too sure everything was indeed working as intended, thus chose not to take the risk of re-enabling it - did I miss something? Cheesy
global moderator
Activity: 3990
Merit: 2717
Join the world-leading crypto sportsbook NOW!
February 07, 2015, 05:42:10 AM
#13
I thought he was talking about just fixing it so avatars could be re-enabled.
legendary
Activity: 2562
Merit: 1071
February 07, 2015, 05:22:14 AM
#12
Well it could but it was just decided not to bother for whatever reasons. Avatars aren't really a priority and they'll be back with the new forum anyway.

Can't a modification be made to the code to avoid that exploit ?

According to mprep, the code was indeed modified to avoid the exploit:

Q: Why doesn't the forum let me add an avatar?
A: The forum was hacked some time ago. It is thought that the avatars were used as a means of injecting malicious code into the forum. Even though the vulnerability was patched, the avatars will be disabled until a new forum software is released.

He didn't go on to say why the feature was not re-enabled in that post but, perhaps that was not done out of concern there could be other related vulnerabilities, as well as that being a low priority feature and the work being put towards the new forum software instead, as hilariousandco mentioned.
global moderator
Activity: 3990
Merit: 2717
Join the world-leading crypto sportsbook NOW!
February 07, 2015, 04:55:38 AM
#11
Well it could but it was just decided not to bother for whatever reasons. Avatars aren't really a priority and they'll be back with the new forum anyway.
Pages:
Jump to: